Safety vulnerabilities have been disclosed in Xerox VersaLink C7025 Multifunction printers (MFPs) that might permit attackers to seize authentication credentials through pass-back assaults through Light-weight Listing Entry Protocol (LDAP) and SMB/FTP companies.
“This pass-back model assault leverages a vulnerability that enables a malicious actor to change the MFP’s configuration and trigger the MFP system to ship authentication credentials again to the malicious actor,” Rapid7 security researcher Deral Heiland stated.
“If a malicious actor can efficiently leverage these points, it will permit them to seize credentials for Home windows Energetic Listing. This implies they might then transfer laterally inside a company’s atmosphere and compromise different crucial Home windows servers and file techniques.”

The recognized vulnerabilities, which have an effect on firmware variations 57.69.91 and earlier, are listed under –
Profitable exploitation of CVE-2024-12510 might permit authentication data to be redirected to a rogue server, doubtlessly exposing credentials. This, nonetheless, requires an attacker to achieve entry to the LDAP configuration web page and that LDAP is used for authentication.
CVE-2024-12511, likewise, permits a malicious actor to achieve entry to the person deal with ebook configuration to change the SMB or FTP server’s IP deal with and make it level to a number below their management, inflicting SMB or FTP authentication credentials to be captured throughout file scan operations.

“For this assault to achieve success, the attacker requires an SMB or FTP scan operate to be configured throughout the person’s deal with ebook, in addition to bodily entry to the printer console or entry to remote-control console through the online interface,” Heiland famous. “This will likely require admin entry except person stage entry to the remote-control console has been enabled.”
Following accountable disclosure on March 26, 2024, the vulnerabilities had been addressed as a part of Service Pack 57.75.53 launched late final month for VersaLink C7020, 7025, and 7030 collection printers.

If rapid patching just isn’t an choice, customers are beneficial to set a fancy password for the admin account, keep away from utilizing Home windows authentication accounts which have elevated privileges, and disable the remote-control console for unauthenticated customers.
The event comes as Specular founder and CEO Peyton Smith detailed an unauthenticated SQL injection vulnerability affecting a extensively deployed healthcare software program named HealthStream MSOW (CVE-2024-56735) that might result in a full database compromise, permitting risk actors to entry delicate knowledge of 23 healthcare organizations from the general public web.
The corporate stated it recognized 50 cases of internet-exposed MSOW cases, of which 23 are prone to security shortcomings.
The vulnerability might permit “the complete database might be returned in-band, which means an attacker might retrieve the plaintext database contents in a HTTP response from a crafted SQL injection HTTP payload,” Smith stated.